CVE-2018-14592
CRITICALCWJoomla <2.0.7, <1.0.6 - SQL Injection
Title source: llmDescription
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0346
EPSS Percentile
87.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (2)
cwjoomla/cw_article_attachments_free
< 1.0.6
cwjoomla/cw_article_attachments_pro
< 2.0.7
Published
Sep 20, 2018
Tracked Since
Feb 18, 2026